8.4

CVE-2023-50975

The TD Bank TD Advanced Dashboard client through 3.0.3 for macOS allows arbitrary code execution because of the lack of electron::fuses::IsRunAsNodeEnabled (i.e., ELECTRON_RUN_AS_NODE can be used in production). This makes it easier for a compromised process to access banking information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TdAdvanced Dashboard SwPlatformmacos Version <= 3.0.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.136
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

https://www.electronjs.org/blog/statement-run-as-node-cves
Issue Tracking
https://gist.github.com/khronokernel/2598c067d0f49b0f0a4c8b01cf129d34
Third Party Advisory
https://newsroom.ripeda.com/tag/macs-for-business/
Broken Link